Executive brief
Snipe-IT, an open-source IT asset management system, contains a vulnerability that allows users with data import permissions to take over other user accounts. By uploading a specially crafted CSV file, an authorized importer can change the email address associated with another account and then use the password reset feature to gain full access. This could lead to unauthorized access to sensitive asset data and administrative functions.
Technical details
A missing authorization check in the CSV user import functionality (specifically in 'update' mode) allows for privilege escalation. While 'UserImporter.php' attempts to strip sensitive authentication fields using a gate check, the 'sanitizeItemForUpdating' method in 'ItemImporter.php' bypasses these unsets by rebuilding the update array directly from the raw CSV input. Consequently, an attacker with 'import' permissions can overwrite the email address of any non-admin user. Once the email is changed, the attacker can initiate a standard password reset flow to hijack the target account. This bypasses the stricter authorization logic found in the standard User API. The issue is fixed in version 8.6.0.
Affected products
- Grokability Snipe-IT < 8.6.0
Timeline
- 2026-06-08: disclosed
- 2026-06-23: advisory
- 2026-06-23: patched: Fixed in version 8.6.0